|
|
| |
|
| |
tinymce-spellchecker: code execution
| Package(s): | tinymce-spellchecker |
CVE #(s): | CVE-2012-6112
|
| Created: | February 4, 2013 |
Updated: | February 6, 2013 |
| Description: |
From the Red Hat bugzilla:
A security flaw was found in the way Google spellchecker of TinyMCE spellchecker plugin sanitized content of $lang and $str arguments from presence of control characters when checking for matches. A remote attacker could provide a specially-crafted string, to be checked by the TinyMCE spellchecker plugin that, when processed, could lead to arbitrary code execution with the privileges of the user running the TinyMCE spellchecker plugin. |
| Alerts: |
|
( Log in to post comments)
|
|
|